Networking & Content Delivery

Category: *Post Types

Implementing encryption in transit across connectivity patterns with VPC Encryption Controls

Security and compliance teams managing modern cloud environments often ask us: “How do we enforce encryption in transit across every network path? Can we put in place policies that restrict teams from sending unencrypted traffic between any two nodes?”. Your environment likely includes a mixed fleet of Amazon Elastic Compute Cloud (Amazon EC2) instances across […]

AWS Interconnect

AWS and Microsoft Azure collaborate to expand multicloud networking

As organizations embrace multicloud strategies at an accelerating pace, the ability to move workloads seamlessly between cloud providers has become essential. Yet establishing resilient, high-performance private connectivity between clouds has historically required customers to navigate complex and diverse physical infrastructure, multiple connectivity providers, and invest weeks or months of manual provisioning. Starting today, customers can […]

Building Multi-Region Active-Active Architectures with CloudFront VPC origins and Advanced Routing

Introduction Building a multi-region active-active architecture with Amazon CloudFront requires careful coordination of traffic routing to address performance, traffic management, and session consistency requirements, along with automated failover to maintain availability during regional events. In November 2024, AWS released Amazon CloudFront VPC origins, which provides direct connectivity to private resources within your Amazon VPC without […]

CloudFront Functions Unified Logging

CloudFront Functions (CF2) lets you run lightweight code inside Amazon CloudFront Points-of-Presences (POPs) to analyze and manipulate viewer requests and responses at scale. Until now, gaining visibility into the decisions your functions made such as the result of a token validation or logging a header returned from origin required collecting the header from CloudFront Realtime […]

Gain visibility into client-side network failures with NEL

Gain visibility into client-side network failures with NEL

When your user experiences a connectivity issue visiting your website, it’s unlikely that you’ll see a trace of it in your server logs. DNS resolution failures happen before your user ever connects to your server. TCP timeouts, on shared infrastructure such as Content Delivery Networks (CDNs), are difficult to attribute to a specific origin. Even […]

Zero-trust networking for agentic AI with Amazon VPC Lattice

Zero-trust networking for agentic AI with Amazon VPC Lattice

Your most sensitive data—patient records, financial data, classified documents—lives in a private Amazon Virtual Private Cloud (Amazon VPC) with no internet access, and for good reason. That network isolation is a deliberate security posture, not an oversight. The problem is that your AI agents need to reason over that data, and traditional networking approaches force […]

Deployment models for AWS Network Firewall: Transit Gateway attachment and multiple VPC endpoints

Deployment models for AWS Network Firewall: Transit Gateway attachment and multiple VPC endpoints

Customers adopting AWS Network Firewall at scale have shared two consistent pieces of feedback. First, managing inspection for centralized deployments adds operational complexity. Second, deploying separate firewalls for each VPC in distributed deployments becomes costly and difficult to manage as the number of VPCs increases. In this post, we explore the architectural patterns for two […]

NetFW Proxy

Reintroducing Network Firewall Proxy for Secure Egress Connectivity

At re:Invent 2025 we launched AWS Network Firewall proxy in preview to gather feedback from customers before making it generally available. That feedback was clear and consistent: customers want the flexibility to use their Network Firewall, with all its existing capabilities, as an explicit proxy. Rather than managing a separate proxy product with its own security policy model, customers told us they would prefer […]

Centralized VPC inspection with Amazon VPC Route Server and AWS Transit Gateway

Centralized VPC inspection with Amazon VPC Route Server and AWS Transit Gateway

Centralized VPC inspection with Amazon VPC Route Server and AWS Transit Gateway helps you route traffic from multiple virtual private clouds (VPCs) through a shared firewall for security enforcement. Spoke VPCs send traffic through AWS Transit Gateway to a dedicated inspection VPC, where firewall appliances examine it before forwarding. The challenge is making this inspection […]

Protect Amazon Route 53 domains during account lifecycle events: Best practices for domain governance in multi-account organizations

Domain governance in Amazon Route 53 can mean the difference between a routine account decommissioning and an unplanned outage. Picture this situation: your organization closes an Amazon Web Services (AWS) account, and five days later a customer-facing website becomes unreachable, email stops flowing, and SSL certificate validation fails. A domain that this account had registered […]